ai · security · skills

For the compliance lead

Four AI regulations. One budget.

Track 2 · Your skills path is one click away. The story below is depth; the path names what to learn.

Build the defender’s skills

Each regime asks the same questions in different words.

Answered one at a time, you’ll evidence the same control five times — and still not know which gaps are real.

8 regimes

are crosswalked in this app onto one control spine of 247 objectives — so what maps is reused, and what doesn’t is a named delta, not a surprise.

the crosswalk, generated verbatim from CSA’s published source files

The regimes aren’t going to harmonise themselves — the EU AI Act, ISO/IEC 42001, NIST each arrived on their own clock.

The spine is how you stop paying that tax: implement once, evidence once, work only the deltas.

What do I implement once — and what’s genuinely new?

One spine, every regime crosswalked onto it. Reuse the evidence; work only the named deltas.

Three artifacts carry the answer — each one precise enough to audit.

One spine

Every control, four ways in.

The spine is the CSA AI Controls Matrix — the control catalogue for AI systems — and this reference lets you enter it from whatever you carry: a domain, a framework obligation, an instrument, or an ownership question.

Each entry lands on the real control objectives and the auditing guidance, not a summary of them.

The control reference, four ways in →

AICM domains, one assess5 domains · 73 controls

GRC · Governance

Governance, Risk and Compliance

Who owns AI risk, who decides, and how policy becomes operating practice.

15 control objectivesskills in progress
Open GRCdrill →

Foundational: Ground floor every function needs before AI-specific controls land.

Four ways into the same control detail — start from whatever you carry.

The crosswalk & deltas

What maps, and what’s genuinely new.

Per regime, control by control: which obligations the spine already satisfies, and which are genuinely new work. The deltas are named — not argued case by case in each audit.

Evidence produced once on the spine is cited per regime, in that regime’s own vocabulary.

The crosswalk, regime by regime →

The comply-once core

The map, explorable.

The comply-once core is the working surface: the spine, the regimes, and the deltas in one explorable map — the thing you’d otherwise maintain in a spreadsheet that’s wrong by March.

The comply-once map, explorable →

Your reskilling list

45 controls have your name on them.

Attributed control by control on the CSA spine, so the audit trail starts before the reskilling does.

6 to build · 28 to coordinate with a provider · 11 to verify, not build. Nobody reskills for what the provider already owns.

Run the AI audit

6 controls

Honor the privacy obligations

10 controls

Assure the supply chain

18 controls

Map the regulations once

5 controls

Keep the people side compliant

6 controls

This is the same spine the assessment reads. Score your mastery on four concrete rungs per prompt, or run the function diagnostic — every gap lands on this list: the named skill, the group it belongs to, and who learns it.

Browse skills personalities →Run the diagnostic. Your gaps land on this list →

247 objectives. 8 regimes mapped.

Deltas named per regime, control by control — not argued case by case.

Browse the controlsSee the crosswalk
Every number above has a method page behind it: each piece opened up as inputs → mechanism → outputs, with provenance — and the deeper tables named, content owner-gated.The method, piece by piece →

Not your role?

Each role has its own way in. Here is where the others start.